The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Report on Securing and Growing the Digital Economy
Report on Securing and Growing the Digital Economy artwork

011 - Imperative 4 Build Cybersecurity Workforce Capabilities

Report on Securing and Growing the Digital Economy · 2026-03-05 · 21 min

0:00--:--

Key moments - from our scoring

Substance score

18 / 100

Five dimensions, 20 points each

Insight Density6 / 20
Originality4 / 20
Guest Caliber0 / 20
Specificity & Evidence8 / 20
Conversational Craft0 / 20

The Commission identifies a persistent gap between open cybersecurity positions and qualified applicants that has lasted nearly a decade, with 86% of employers forced to provide on-the-job training to entry-level staff who lack necessary technical skills. Beyond recruiting dedicated cybersecurity professionals, the report emphasizes that cybersecurity knowledge must become baseline competency across all workforce levels - from frontline employees to C-suite executives and mid-level managers. The Commission proposes a national surge combining immediate workforce expansion through boot camps and apprenticeships, long-term STEM education initiatives starting in preschool, and executive training programs. Key recommendations include establishing a National Cybersecurity Workforce program to train 100,000 practitioners by 2020, launching a 50,000-person apprenticeship program, creating Presidential Cybersecurity Fellows positions, and developing standardized cybersecurity curricula through NIST's National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework. The report also calls for public-private partnerships to reduce student debt through loan forgiveness programs and expanded use of successful models like NSF's CyberCorps Scholarship for Service Program and the White House TechHire Initiative.

Key takeaways

  • →The nation needs to train 100,000 new cybersecurity practitioners by 2020 through a national workforce program combining federal funding and local-regional employer and educational institution partnerships.
  • →Entry-level cybersecurity positions require not only dedicated recruits but also baseline cybersecurity awareness training integrated into K-12 education and mandatory executive training for federal managers regardless of their mission area.
  • →Cybersecurity boot camps and apprenticeship programs should be designed to specifically target underrepresented populations including women, minorities, veterans, and older workers seeking career changes.
  • →Federal and private sector exchange programs and rotational assignments are recognized best practices for building surge capacity and retaining mid- and senior-level cybersecurity specialists.
  • →Standardized cybersecurity curricula developed by NIST, NSF, NSA, and the Department of Education - and enforced through accreditation boards like ABET - are needed to address the wide range of disconnected degree programs and certificates currently available.

In this episode

  1. 1The Cybersecurity Workforce Gap and National Challenge
  2. 2Root Causes: STEM Education and Entry-Level Skills Shortage
  3. 3Expanding Workforce Through Public and Private Sector Collaboration
  4. 4Building Capacity and Scaling Current Successful Programs
  5. 5National Cybersecurity Workforce Training Program for 100,000 Practitioners
  6. 6Apprenticeship and Training Initiatives for Entry and Mid-Level Skills
  7. 7Cybersecurity Awareness Education from Preschool to High School
  8. 8Manager and Executive Training in Cybersecurity Risk Management

Mentioned

Commission on Enhancing National CybersecurityNational Science FoundationNISTNational Security AgencyOffice of Personnel ManagementISCAssociation for Computing MachineryInstitute of Electrical and Electronics EngineersAccreditation Board for Engineering and TechnologyNICE Cybersecurity Workforce FrameworkCybersecurity National Action PlanGenCyber

Topics in this episode

CybersecurityNICE Cybersecurity Workforce FrameworkNational Science Foundation (NSF)National Initiative for Cybersecurity Education (NICE)CyberCorps Scholarship for Service ProgramNational Cybersecurity Action Plan (CNAP)Federal Cybersecurity Workforce Assessment Act of 2015TechHire InitiativePresidential Cybersecurity Fellows programGen Cyber summer campsNSA Centers of Academic Excellence in Cybersecurityfutureeconomygovernmentdefense

Questions this episode answers

How many cybersecurity professionals does the U.S. need to hire and by what year?

According to the 2015 ISC Global Information Security Workforce Study cited in the report, 1.5 million more cybersecurity professionals will be needed globally by 2020, with the Commission recommending specific national programs to train 100,000 new practitioners by 2020 and an additional 50,000 through apprenticeships.

What percentage of entry-level cybersecurity staff require on-the-job training?

One recent study found that 86% of employers must provide on-the-job training to entry-level cybersecurity staff because most lack the necessary technical skills.

What is the NICE Cybersecurity Workforce Framework?

The NICE framework, published by NIST, identifies several broad categories of cybersecurity work with more than 30 specialty areas and more than 50 work roles, and is being used by the federal government to assess current workforce gaps and guide curriculum development at educational institutions.

What successful cybersecurity education programs does the report recommend scaling up?

The report recommends expanding programs including NSF's CyberCorps Scholarship for Service Program, state models like Virginia's Cybersecurity Public Service Scholarship, NSA's Centers of Academic Excellence in Cybersecurity, and Gen Cyber summer camps run by NSF and NSA for K-12 students and teachers.

What federal position does the report recommend creating to attract cybersecurity leaders?

The report recommends OPM establish a Presidential Cybersecurity Fellows program modeled on the Presidential Management Fellows Program, with the goal of bringing 200 cybersecurity specialists into federal civilian agencies by 2020.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

6 / 20

The transcript is primarily a recitation of existing government policy recommendations and well-known statistics (1.5M shortage, 86% need on-the-job training) without novel insights or original analysis. It reads as a formal policy document listing action items rather than a discussion that challenges assumptions or reveals non-obvious truths about cybersecurity workforce development.

According to the twenty fifteen ISC Global Information Security Workforce Workforce Study, one point five million more cybersecurity professionals will be needed global t twenty.
one recent study found that most entry level staff lack the necessary technical skills, and as a result, eighty six percent of employers must provide on the job training.

Originality

4 / 20

The content relies entirely on standard policy frameworks (NICE Workforce Framework, NSF programs, STEM initiatives) and conventional solutions (bootcamps, apprenticeships, loan forgiveness) that have been circulating in government cybersecurity discourse for years. There is no contrarian thinking, first-principles reasoning, or unconventional approaches presented.

The federal government must work with the private sector to attract more students to the field of cybersecurity.
bootcamp initiatives and federal programs supporting education at all levels should incorporate cybersecurity awareness

Guest Caliber

0 / 20

This is not a podcast interview with guests. It is a LibriVox audiobook recording of a government report being read aloud by J.D. Gibson, a volunteer narrator. There are no practitioners, operators, or subject-matter experts being interviewed or sharing direct experience.

This is a LibriVox recording. All LibriVox recordings are in the public domain.
Recording by J. D. Gibson.

Specificity & Evidence

8 / 20

The transcript includes some specific numbers (1.5M shortage, 86% training requirement, 100K practitioners by 2020, 50K apprenticeships by 2020, 200 fellows by 2020) and names specific programs (NICE Framework, NSF, NSA, Tech Hire Initiative, gen Cyber). However, evidence is thin on actual outcomes, company examples, or concrete metrics showing what works, making it more of a policy wishlist than evidence-based guidance.

one point five million more cybersecurity professionals will be needed global t twenty
the next president should initiate a national Cybersecurity Workforce program to train one hundred thousand new cybersecurity practitioners by twenty twenty

Conversational Craft

0 / 20

There is no conversation, no host, no questions, and no dialogue. This is a straightforward reading of government policy text with zero conversational elements, follow-up questions, or intellectual sparring. It is a document narration, not a podcast conversation.

This is a LibriVox recording.
Section ten of Report on Securing and Growing the Digital Economy.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

cybersecurity82workforce29program21point20federal20national18government18programs17private14sector13training13four12skills12students12education12twenty11

Episode notes

On April 13, 2016, President Obama established The Presidents Commission on Enhancing National Cybersecurity to devise a comprehensive strategy for safeguarding our cyberspace and the economic foundations built upon it. The commissions final report, published in December 2016, provides a thorough examination of the current state of cybersecurity, anticipates future challenges, and presents actionable recommendations for the incoming Trump administration and future leaders. It emphasizes the critical roles that the military, government, and private sector must play in strengthening our defenses against cyber threats. Join us as we explore the insights and strategies laid out in this pivotal report. - Summary by TriciaG

Full transcript

21 min

Transcribed and scored by The B2B Podcast Index.

Section ten of Report on Securing and Growing the Digital Economy. This is a LibriVox recording. All LibriVox recordings are in the public domain. For more information or to volunteer, please visit LibriVox dot org.

Recording by J. D. Gibson. Report on Securing and Growing the Digital Economy by the Commission on Enhancing National Cybersecurity Imperative four Build cybersecurity workforce capabilities.

The challenge and way forward Meeting the critical national and economic security need to expand and strengthen an agile cybersecurity workforce will require a national effort that engages all levels of the public sector as well as the private sector. According to the twenty fifteen ISC Global Information Security Workforce Study, one point five million more cybersecurity professionals will be needed global t twenty. Cybersecurity offers a premium in pay over other fields in information technology, yet a sizeable gap between open positions and qualified applicants has persisted for almost a decade.

Both the quantity and the quality of those applying for positions remain significant problems, as does the challenge of ensuring that training is up to date and effective. One recent study found that most entry level staff lack the necessary technical skills, and as a result, eighty six percent of employers must provide on the job training. In addition, an increasing number of occupations will demand some level of cybersecurity knowledge. Within the United States, there are millions of companies and businesses, tens of thousands of local governments and public school systems, and hundreds of millions of personal computer users.

This growing number includes members of the workforce at all levels, with mid and senior level managers among those who will need to regularly improve their cybersecurity skills. It is just as important that the general workforce and executives receive training as it is that cybersecurity professionals be recruited and kept current. Every one of these organizations and people will need a baseline knowledge of cybersecurity to perform their jobs effectively. To address this shortage, we must expand our current efforts to draw more workers into the cybersecurity field.

The work shortage in cybersecurity is directly related to a larger problem. Too few high school and college students in the United States are developing the skills necessary for careers in science, technology, engineering, and mathematics STEM, even while more is being done to encourage and sustain interest in stem the economic and national security of the United States cannot wait a day, decade or longer for initiatives in primary and secondary education to bear fruit. Closing the gap in the near term will require a national surge that increases the workforce and provides a structure on the job training to ensure that the current workforce has the right skill set.

This surge would benefit both the private and public sectors by increasing the number of employee candidates who are qualified to address urgent cybersecurity needs. Moreover, movement between sectors would benefit all concerned, especially over time, as cybersecurity specialists gain experience in different environments and domains. To increase the number of qualified entry level cybersecurity practitioners, the federal government must work with the private sector to attract more students to the field of cybersecurity.

These collaborative efforts also should aim to create pathways into the field for unprecedented populations such as women, minorities, and veterans and older workers seeking career changes or hoping to leave professions with fewer opportunities. The current focus on retraining veterans for careers in cybersecurity should be continued and expanded. The Commission recognizes the possibility that advances in automation, artificial intelligence, and machine learning may slow and possibly reverse the demand for more workers in the field.

However, the Commission also notes that cybersecurity work roles and responsibilities are increasingly being integrated into a growing array of jobs at all levels with nearly all organizations. Unlike the skills needed for jobs in other sectors such as manufacturing or retail, a strong technical grounding in cybersecurity will create opportunities for employment in a number of different types of jobs in the current and future digital economy. In addition, the effects of automation, machine learning, and artificial intelligence on cybersecurity workforce demand will likely not be realized by most enterprises for several years or longer.

The nation needs to surge its cybersecurity workforce today. This report, like many assessments of our nation's cybersecurity needs, tends to focus on the number of cybersecurity professionals and the education and training programs required to meet our current and future needs. The Commissioners also note, however, that some of the most important advances in organization's cybersecurity derive from the work of creative individuals who developed new concepts and approaches to address cybersecurity challenges.

No formula or specific recommendation can lead to their breakthroughs, and such efforts cannot be quantified, but it is important to ensure that we continue to create environments that encourage and reward them. Encouraging innovation, which is one of the foundational principles of this report, has made the United States the global leader in technological innovation, especially in driving the information revolution. Workforce recommendations related to federal, state, local, tribal, and territorial governments, including enlisting the capabilities of the National Guard, are provided below and in Imperative five Action Item five point five point three.

Many of these recommendations build on the Federal Cybersecurity Workforce Strategy that OMB and the Office of Personnel Management o PM issued in July twenty sixteen, and will further the goals outlined in that strategy Recommendation four point one. The nation should proactively address workforce gaps through capacity building, while simultaneously investing in innovations such as automation, machine learning, and artificial intelligence that will redistribute the future required workforce.

The cybersecurity workforce is expected to continue to grow over the next several years, but not at a rate commensurate with the growing threats. Consequently, we need to continue to expand existing initiatives and develop new ones that will grow our nation's workforce. Building on current successful efforts is an important first step. The National Science Foundation in SF supports capacity building and institutions of higher education through the Cybercourt Scholarship for Service Program.

This federal program's success has resulted in the establishment of complementary state models, such as the Virginia Cybersecurity Public Service Scholarship. The Cybersecurity National Action Plan CNAP also contains new cybersecurity education and workforce initiatives, including enhancements to student loan forgiveness programs for cybersecurity experts joining the federal workforce. The National Initiative for Cybersecurity Education NICE Cybersecurity Workforce Framework, published recently by NIST, identifies several broad categories of cybersecurity work with more than thirty specialty areas and more than fifty work roles.

The federal government is using the NICE framework to assess its current cybersecurity workforce and identify gaps, as required by the Federal Cybersecurity Workforce Assessment Act of twenty fifteen. These programs and others that have been successful should be scaled up and grown with funding increased to a level commensurate with the scale of the National Workforce Shortage Action Item four point one point one. The next president should initiate a national Cybersecurity Workforce program to train one hundred thousand new cybersecurity practitioners by twenty twenty.

Short term, a national cybersecurity workforce program would help our nation develop cybersecurity tis talent pipelines. Such a program with a specific focus on local and regional partnerships of employers, educational institutions, and community organizations will help develop the skilled workforce necessary to meet the cybersecurity needs of local and regional industry. One successful example is the tech Hire Initiative launched by the White House in twenty fifteen, which expands local technology sectors by providing technology talent pipelines in communities across the country.

The federal government and private sector partners should also jointly sponsor a nationwide network of cybersecurity boot camps aimed at providing knowledge and skills in a condensed time frame. These training initiatives will increase the supply of practitioners and allow the redeployment of individuals who are currently underemployed or unemployed. Boot Camps are also an excellent way to identify underrepresent populations of cybersecurity workers, such as women and minorities, and to develop targeted recruitment and training efforts in cohorts that maximize the opportunity for completing the program and transitioning into the workforce.

Action Item four point one point two, the next President should initiate a national Cybersecurity Apprenticeship program to train fifty thousand new cybersecurity practitioners by twenty twenty. Medium term, the program should have pathways for students in traditional four year university programs and two year community college programs with a specific focus on developing the skills necessary to begin a career in cybersecurity. The program should also have a specific focus on developing outside of traditional academic settings, the skills necessary to begin a career in cybersecurity.

The initiative should promote the development of entry level and mid level skills in US, including in students graduating with engineering, computing or IT degrees with excellent technical skills but little actual cybersecurity training followed by hands on apprenticeships both in government and in the private sector. Action Item four point one point three to better prepare students as individuals and future employees. Federal programs supporting education at all levels should incorporate cybersecurity awareness for students as they are introduced to and provided with Internet based devices.

Short term cybersecurity awareness messages should be developed and focused on children as early as preschool and throughout elementary school. This cybersecurity education must include programs to train and better prepare teachers in order to succeed at scale. Successful programs such as the NSF and National Security Agency and say run gen Cyber, which provide its summer cybersecurity camp experiences for students and teachers at the K through twelve level, should be leveraged to help all students understand safe online behavior and to increase diversity and interest in cybersecurity careers.

This effort would also stimulate exploration of cybersecurity careers in middle school and enable preparedness for cybersecurity careers in high school. In addition, the process of exposing young people to technology and the associated safety, security, ethical, and legal issues will introduce them to a broad range of academic and career pathways that can sustain lifelong employment. Action Item four point one point four. The federal government should develop a mandatory training program to introduce managers and executives to cybersecurity risk management topics, even if their role is not focused on a cybersecurity mission area, so that they can create a culture of cybersecurity in their organizations short term.

To successfully address and integrate cyber risks within a risk management framework, agency leaders need to have sufficient knowledge of cyber risks, threat mitigation strategies, cyber performance metrics, and related factors, regardless of their agency mission, because cybersecurity is a core part of every agency's mission. In this sense, such knowledge is no different than the basic finance, procurement, human resources, and other business skills expected of every senior leader within an agency.

However, little priority has been given to seeking government executives or agency leaders with these skills or providing individuals the opportunity to develop them in the near term. The knowledge, skills, and experience needed for cyber risk management should be integrated into the executive training and development programs for all federal agencies. In effect, a cyber MBA should be designed for government executives. The senior executive services sees should be prioritized to receive this training.

Cyber risk elements should be systematically incorporated into ses, training selection, performance evaluation, and professional development. Such programs are well defined within federal agencies, and these executives are often the primary interface between the program specialists and the political leadership of a department or agency. The training then should be expanded to other management levels Action Item four point one point five. The federal government SLTT, governments and private sector organizations should create an exchange program aimed at increasing the cybersecurity experience and capabilities of mid level and senior level employees.

Short term, both the public sector and the private sector are experiencing an acute cybersecurity workforce shortage. One of the most important attributes of a cybersecurity worker is the experience she or he obtains while on the job, whether working in government or in industry. Rotational assignments within the government or private sector are starting to be recognized as a best practice for retention. These assignments lay the groundwork for a surge capacity, making it possible to deploy individuals quickly and flexibly as situations warrant.

This exchange program should embrace innovative approaches to workforce management, including support for virtual employment exchanges, and seek to extremeline administrative processing and address potential barriers to participation that could hinder private sector rotations into the federal government, for example, security clearance processing, existing or potential contract relationships Regularly Actions Action Item four point one point six. The Office of Personnel Management OPM should establish a Presidential Cybersecurity Fellows program for federal civilian agencies with the goal of bringing on two hundred cybersecurity specialists by twenty twenty.

Short term, aspiring and seasoned cybersecurity managers and leaders are in high demand in government and industry alike. To attract more managers and senior leaders to federal government service, OPM should establish Presidential Cybersecurity Fellows through a program similar to the Presidential Management Fellows Program, but focused on cybersecurity through a competitive application process. This program would bring individuals into government and place them in cybersecurity positions with responsibilities relating both to technology and policy areas.

The program would be open to students who recently completed graduate programs and to faculty or seasoned professionals for students or mid career professionals. This program would provide career development opportunities and expose a new generation of aspiring leaders to the possibilities and rewards of a career in federal government service as a cybersecurity, technology or policy specialist. Action Item four point one point seven in IST, the National Science Foundation in SF, the National Security Agency in SA, and the Department of Education should work with private sector organizations, universities, and professional societies to develop, standardize, interdisciplinary cybersecurity curricula that integrate with and expand existing efforts and programs medium term.

As the cybersecurity profession continues to evolve and mature, so too do efforts to create curricula, degree programs, and certificates of study in cybersecurity. There is a wide range of academic options as various cybersecurity and privacy degrees, certificates, and concentrations have emerged. Many efforts are now underway to develop curricular guidance for cybersecurity, such as work undertaken by the Association for Computing Machinery and the Institute of Electrical and Electronics Engineer's Joint Task Force on Cybersecurity Education, and a new curriculum effort led by NSA under CNAP, the NSA DHS Centers of Academic Excellence in Cybersecurity are incentivizing institutions to map their curriculum and degree programs to knowledge units aligned to NIST's National Initiative for Cybersecurity Education NICE Cybersecurity Workforce Framework.

Despite these nascent endeavors, including similar initiatives at the high school level, no common body of no KNOWNLGE UDGE or core curriculum has yet been agreed on or widely adopted. We need a concerted national effort to inventory existing curricula and initiatives, identify gaps, and develop and disseminate a standardized set of guidelines and resources to guide teachers and administrators. This effort should also pursue collaborations with organizations that accredit college and university programs in scientific, engineering and computing disciplines, such as the Accreditation Board for Engineering and Technology ABT.

Cybersecurity should be a basic requirement for the accreditation of any programs in engineering and computing disciplines Action Item four point one point eight in order to attract more students to pursue cybersecurity degree programs and enter the cybersecurity workforce in both the public and private sectors. Incentives should be offered to reduce student debt or subsidized the cost of education through a public private partnership. Medium term, the increase in the cost of college and in student debt is an enormous public policy challenge.

The private sector should structure a program that provides financial support, that is, scholarships, loan forgiveness, tuition reimbursement for students who earn vocational, polytechnic, or master's degree in related cybersecurity fields, specifically in exchange for a period of service within the federal government followed by a period of employment at a sponsoring company. That company will cover education expenses, for example student aid. The program would help the federal government to address a significant talent deficit and would provide the private sector with a pool of experienced cybersecurity professionals who possess federal government relationships and experience.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Mastercard CEO: AI Shopping Agents, Machine-to-Machine Payments, and the New Infrastructure of CommerceMotley Fool Hidden Gems Investing · on Cybersecurity88 / 100
  • Why Most Startups Fail: Founders Don’t Know What They Don’t Know YetBuilt Not Born: The Startup Go-To-Market Podcast · on Cybersecurity80 / 100
  • Episode 46 - from Tashkent to Termsheet with Victor OrlovskyThe GoingVC Podcast · on Cybersecurity77 / 100
  • Moving from Product Partnerships to Revenue: Jira Cooley on Owning the NumberBetween Product and Partnerships · on Cybersecurity76 / 100
  • Reframing Marketing ROI to Return on Objectives with Karl Van den BerghThe B2B CMO Podcast with Jon Miller and Sydney Sloan · on Cybersecurity75 / 100
  • Help Desk Heroes No More: Why Your IT Guy Now Talks StrategyNerds On Tap · on Cybersecurity72 / 100

More from Report on Securing and Growing the Digital Economy

All episodes →
  • 017 - Appendix 6 Cybersecurity Legislation Overview26 / 100
  • 016 - Appendix 5 Cybersecurity Policy Overview31 / 100
  • 015 - Appendix 4 Executive Order 1371826 / 100
  • 014 - Appendix 1 Imperatives Recommendations and Action Items26 / 100
  • 013 - Imperative 6 Ensure an Open Fair Competitive and Secure Global Digital Economy IV Next Steps36 / 100
All Report on Securing and Growing the Digital Economy episodes →